PkgRadar

Cargo · crates.io

cargo-rullst

Rs Build Time Command: Process spawn (std::process::Command) at build time.

Why PkgRadar flagged 3.0.0

SeveritySignalEvidence
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · cargo-rullst-3.0.0/src/generators/build.rs
mediumRemote Payloadmatched "curl " · cargo-rullst-3.0.0/src/generators/foundry.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.0Review472026-06-16
2.0.10Review472026-06-14
2.0.9Review472026-06-12
2.0.8Review472026-06-12
2.0.7Review472026-06-10
2.0.6Review472026-06-10
2.0.5Review472026-06-10
2.0.4Review472026-06-09
2.0.3Review472026-06-08
2.0.2Review472026-06-03
2.0.1Review472026-06-03
2.0.0Review472026-06-02
1.0.14Low risk02026-05-30
1.0.13Low risk02026-05-30
1.0.11Low risk02026-05-30
1.0.10Low risk02026-05-29
1.0.9Low risk02026-05-29
1.0.7Low risk02026-05-28

Block this in CI

PkgRadar gates cargo-rullst (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]